The Offside Wallet Theft Factory Firefox Add-ons
Updated 5 Oct 2026 · Incident date 9 Mar 2026 · browser extension
9 Firefox add-on IDs first published as sports-score tools, later updated into fake OKX / Rabby / TronLink wallet stealers (part of 77 tracked identities)not named by Socket, but version pairs are published, e.g. bright-save-feed@tabtools.org v7.4.0Nine Firefox add-on IDs, first published as harmless sports-score tools, were later updated into fake Rabby wallet add-ons that steal recovery phrases. Socket named the campaign the Offside Wallet Theft Factory and linked 77 add-on identities to it.
Mozilla signing records for the campaign run from 9 March to 3 August 2026. Socket did not identify confirmed victims or total losses.
What happened
Operators published add-ons that looked like sports tools, then pushed updates under the same Firefox IDs that carried wallet-stealing code. Socket's report counts 77 linked identities. Of these, 40 are confirmed malicious and 37 are sports-score shells. The shells advertised unrelated functions such as password generation, VPN, screenshots and note-taking, but showed sports scores.
Nine of the malicious IDs began as sports-score shells for football, basketball, NBA or American football. Later versions under the same IDs became fake wallets that impersonate Rabby, OKX or TronLink. A user who installed the harmless version received the update through the normal add-on update path.
Socket groups the 40 malicious add-ons by method.
- Seven query attacker-controlled Supabase projects to fetch phishing URLs, so the operators change targets without a new release.
- Fifteen send secrets to Cloudflare Workers. Five of these are modified Rabby builds that capture 12 or 24 word recovery phrases.
- Thirteen are modified Rabby builds that change
persistAllKeyrings()to send serialized keyring data before encryption, by plain HTTP POST. - Five collect credentials and clipboard contents and send them to a hardcoded server.
CryptoSlate and CyberInsider report the same counts and the same March to August 2026 window.
Affected versions
Nine Firefox IDs are confirmed to have changed from a sports version to a wallet-stealing version. Socket lists these pairs.
| Firefox ID | Sports version | Malicious version |
|---|---|---|
bright-save-feed@tabtools.org | Quick Quick 7.4.0 | Rabbit For Desktop 8.20.10 |
swift-clip-link@fasttools.co | Dial Open Pro 7.23.25 | Web3 & EVM 9.50.10 |
deep-tip-sharp@browsify.co | Quick Shield 5.7.1 | Rby-WALLET 6.7.10 |
bolt-save-vault@devplugs.co | Lite Swatch 6.5.21 | abby-WALLET 7.10.10 |
core-note-nova@webtools.net | Key Pulse 8.1.21 | RABB-Wallet 8.22.30 |
gear-save-tip@extrakits.example | Timer Pulse 5.5.5 | Rabbit WALLET 11.10.10 |
flex-lab-save@foxplugin.co | Track Quick 6.10.24 | RabbWALLET 7.10.30 and 8.10.30 |
pure-net-snap@fasttools.co | Store Plus 8.3.18 | Rabb WALLET 9.11.30 |
fast-zip-true@smartext.co | Pomodoro Plus 9.13.24 | RABB-WALLET 10.20.10 |
Socket's names use look-alike characters, so the table shows plain forms. Match on the Firefox ID. Mozilla removed live add-ons during the investigation.
Indicators of compromise
Socket lists these indicators. Defanged forms are written as in the report.
- Cloudflare Worker
dry-bush-5408[.]animalrescueeducationcenter-org[.]workers[.]devwith campaign tokenEQOx7EIPZSNi - Other Workers:
winter-smoke-a612[.]icy-star-f45c[.]workers[.]dev,quiet-thunder-ade3[.]bankoganger[.]workers[.]devandwinter-waterfall-0606[.]rihaniomar21[.]workers[.]dev - Keyring exfiltration hosts
gemachriverdale[.]org:9000ande-wl[.]com:9000 - Server
77[.]91[.]100[.]175, paths/html/app[.]phpand/html/continue[.]php - Phishing page
portal-web3-extension-welcome[.]pages[.]dev/home, loaded by the add-on0KX WEB3 - Supabase project IDs
kyfyvuwifdukctqyggto,acrfruxtmulgvyvtbwgq,efiukydskwkeatexavdp,mzghdnikguesdamuxjbm,nxsixihozitybwrbahiu,yvqmtnmeivrcyomyeouzandvgksucdjccsojzuhckzk - A shared API-Sports credential in the 32 football shells, which query
v3.football.api-sports.io/fixtures?live=all
How to check
List your installed Firefox add-ons and search for the nine IDs. On macOS, this command reads your profile data and changes nothing. On Linux, use ~/.mozilla/firefox as the path.
grep -lE "bright-save-feed@tabtools.org|swift-clip-link@fasttools.co|deep-tip-sharp@browsify.co|bolt-save-vault@devplugs.co|core-note-nova@webtools.net|gear-save-tip@extrakits.example|flex-lab-save@foxplugin.co|pure-net-snap@fasttools.co|fast-zip-true@smartext.co" ~/Library/Application\ Support/Firefox/Profiles/*/extensions.json
A file name in the output means one of the IDs is or was installed in that profile. Also open about:support in Firefox and read the Extensions list for any wallet add-on you did not install on purpose.
What to do now
- Remove any matching add-on from Firefox.
- If you typed a recovery phrase or private key into one of these add-ons, treat it as stolen. Socket states that removing the add-on cannot revoke a secret that was already sent.
- Create a new wallet from a new recovery phrase and move your remaining assets to it.
- If only credentials or clipboard contents were exposed, change the passwords, end active sessions and check destination addresses before you send funds.
- Review add-on activity after each update, because these add-ons changed after install.
This case shows an update that adds a new capability to an artifact that was clean before. Vigilance compares the version you trust with a new one and reports the file that gained a new capability. See the full attack list and download Vigilance.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 73 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE background.js It downloads from the internet and reads saved passwords and access keys.
Frequently asked questions
What is the Offside Wallet Theft Factory?
It is the name Socket gave to a campaign of 77 linked Firefox add-on identities. Forty are confirmed malicious wallet stealers and 37 are sports-score shells. Mozilla signing records run from 9 March to 3 August 2026.
How did harmless Firefox add-ons become wallet stealers?
Nine add-on IDs first shipped as sports-score tools. Later updates under the same Firefox IDs replaced them with fake Rabby and other wallet add-ons that capture recovery phrases and send them out.
What do I do if I entered a recovery phrase into one of these add-ons?
Treat the phrase as stolen. Create a new wallet from a new recovery phrase and move your remaining assets to it. Removing the add-on does not revoke a secret that was already sent.
Sources
More supply chain attacks
- QuickLens / ShotBird ownership-transfer hijack 17 Feb 2026
- Trust Wallet browser extension v2.68 compromise 24 Dec 2025
- RedDirection campaign (Color Picker Geco and 17 others) 27 Jun 2025
- Cyberhaven Chrome extension compromise 25 Dec 2024
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.